Policy-based key recovery
US10263775B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 23, 2017 |
| Grant date | Apr 16, 2019 |
| Priority date | — |
| Expiry date | Oct 6, 2037 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L2463/062
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A device establishes a key recovery policy and generates a key that is protected based on the key recovery policy. The key recovery policy indicates which combinations of other entities can recover the protected key. The device generates different shares of the protected key, each share being a value that, in combination with the other share(s), allows the protected key to be recovered. Each share is associated with a particular leaf agent, the device encrypts each share with the public key of the leaf agent associated with the share and provides the encrypted share to a service. When recovery of the protected key is desired, a recovering authority can generate the protected key only if the recovering authority receives decrypted shares from a sufficient one or combination of leaf agents as indicated by the recovery policy.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.